Ransomware continues to extract payments from roughly half of all victim organizations, even as ransom demands climb and a growing number of governments consider or enact laws that would make paying attackers illegal. The tension between operational survival and emerging legal prohibition is sharpening for healthcare organizations, which remain among the most frequently targeted sectors and face the added pressure of disrupted patient care every hour systems are offline.
The payment calculus
Research published in 2025 by cybersecurity group Sophos found that approximately 47 percent of ransomware victims ultimately pay the demanded ransom. The median demand has been rising year over year, meaning organizations that do pay are writing larger checks than their predecessors — with no guarantee that decryption keys will work or that stolen data will not surface anyway.
For healthcare operators, the calculation carries dimensions that other industries do not face at the same intensity. Clinical systems — electronic health records, imaging platforms, pharmacy dispensing, laboratory interfaces — are not discretionary infrastructure. Downtime translates directly to care delays, patient diversions, and in documented cases, adverse outcomes. That dependency has historically made healthcare a preferred target precisely because the pressure to restore operations quickly is acute.
Where payment bans stand
The UK has signaled intent to restrict ransomware payments, and several other jurisdictions are studying similar measures. The underlying logic is straightforward: as long as payments remain legal and economically rational for victims, the ransomware business model is self-sustaining. Banning payments, proponents argue, collapses the revenue stream that funds criminal infrastructure.
The practical effect on healthcare would be significant. An outright ban would remove payment as a recovery option even when encrypted backups are unavailable or restoration timelines stretch into weeks. That shift would require organizations to treat incident preparedness — tested offline backups, documented manual workflows, rehearsed downtime procedures — not as contingency planning but as the primary recovery strategy. US policymakers have not enacted a federal ban, but HHS has historically discouraged payments, and any move by Congress or the Treasury Department's Office of Foreign Assets Control to tighten restrictions would hit healthcare operators quickly given the sector's exposure.
What the trend means for incident planning
The rising demand figures and the payment-ban debate together point to a structural shift in how healthcare organizations need to approach ransomware preparedness. Several implications stand out:
- Backup architecture is now a regulatory concern, not just an IT preference. The HIPAA Security Rule's contingency planning standard (45 CFR § 164.308(a)(7)) already requires data backup plans and disaster recovery procedures. Organizations that cannot restore from backup within an operationally acceptable window are both clinically and legally exposed if payment becomes prohibited.
- Cyber insurance terms are tightening. Insurers have begun excluding or capping ransomware coverage, and some policies condition coverage on demonstrated controls — tested backups, endpoint protection, and staff training — making documentation of those controls a financial issue, not only a compliance one.
- Negotiation and delay tactics have limits. Engaging a ransomware actor to buy time for restoration is a recognized tactic, but it depends on having something to restore to. Organizations without tested recovery infrastructure gain little from negotiating time they cannot use.
- Law enforcement engagement thresholds are shifting. FBI and CISA guidance continues to encourage reporting before payment. As payment restrictions evolve, early law enforcement contact may transition from advisory to legally consequential.
What the next 12 months may bring
If major English-speaking jurisdictions move to ban ransomware payments, US policymakers will face renewed pressure to follow, particularly in an environment where federal agencies have already emphasized that payments to sanctioned actors can trigger OFAC violations regardless of intent. Healthcare organizations that have deferred investment in air-gapped backups, tabletop exercises, and documented manual downtime procedures may find that the policy window for "pay and recover" closes faster than their remediation timelines allow.
The Sophos data also signals that threat actors are not retreating. A 47 percent payment rate with a rising median demand is a commercially successful model, and healthcare's structural dependency on uptime makes the sector an enduring target. Organizations that treat ransomware response planning as a once-a-year checkbox exercise rather than a continuously tested operational capability are taking on risk that neither insurance nor post-incident payment negotiations can fully offset.